Skip to main content

Improper Removal of Sensitive Information Before Storage or Transfer in follow-redirects

CVE-2022-0536

  • follow-redirects
  • org.webjars.npm:follow-redirects
Severity Medium
Score 5.9/10

Summary

Exposure of Sensitive Information to an Unauthorized Actor in NPM follow-redirects prior to 1.14.8.

  • HIGH
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-212 - Improper Removal of Sensitive Information Before Storage or Transfer

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Advisory Timeline

  • Published